<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Dual WAN IPSec with BGP]]></title><description><![CDATA[<p dir="auto">Hello all, I have the following setup and I would like to know how it is better to configure my pfsense devices.</p>
<p dir="auto"><strong>Site A</strong><br />
Dual WAN pfsense - Provider X &amp; Provider Y</p>
<p dir="auto"><strong>Site B</strong><br />
Dual WAN pfsense - Provider X &amp; Provider Y</p>
<p dir="auto">Two IPSec tunnels between site A and site B</p>
<p dir="auto">IPSec 1: Site A provider X with Site B Provider X<br />
IPSec 2: Site A Provider Y with Site B Provider Y</p>
<p dir="auto">both IPSec tunnels are Routed IPSec and for both of them I am using BGP (I configured two BGP neighbors in every side).</p>
<p dir="auto">My problem is that every time that I am configuring the second IPSec and I configure the BGP neighbor, I loose connectivity.</p>
<p dir="auto">Am I doing something wrong in the configuration? What I want to achieve is having BGP taking care of any line failure and send the traffic to the other IPSec when the one IPSec is down. So basically I need it for failover.</p>
<p dir="auto">Thank you in advance.</p>
]]></description><link>https://forum.netgate.com/topic/161774/dual-wan-ipsec-with-bgp</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 22:16:26 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/161774.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 05 Mar 2021 13:45:04 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Dual WAN IPSec with BGP on Thu, 29 Apr 2021 20:23:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/metisit">@<bdi>metisit</bdi></a> Still no progress as I am facing some other issues here.</p>
<p dir="auto">Honestly I start thinking to revert to normal static IPSec, but the fact that I won't have to step in in the middle of a "crisis" and let BGP do its job, keeps my faith to this configuration.</p>
<p dir="auto">As soon as I solve the other issue that I have, I will give it a shot.</p>
<p dir="auto">According to Netgate support, what I mention at the beginning is totally reasonable and can happen.</p>
<p dir="auto">I'll keep you posted.</p>
<p dir="auto">Chris</p>
]]></description><link>https://forum.netgate.com/post/980585</link><guid isPermaLink="true">https://forum.netgate.com/post/980585</guid><dc:creator><![CDATA[ChrisT]]></dc:creator><pubDate>Thu, 29 Apr 2021 20:23:56 GMT</pubDate></item><item><title><![CDATA[Reply to Dual WAN IPSec with BGP on Thu, 22 Apr 2021 23:09:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/christ">@<bdi>christ</bdi></a> i am looking for a good solution to that use case as well. any progress on your side?</p>
]]></description><link>https://forum.netgate.com/post/979425</link><guid isPermaLink="true">https://forum.netgate.com/post/979425</guid><dc:creator><![CDATA[metisit]]></dc:creator><pubDate>Thu, 22 Apr 2021 23:09:23 GMT</pubDate></item></channel></rss>